99% of critical vulnerabilities are never exploited by anyone

· · Security Deep dive

Corrected on 4 October 2026: the figures have been revised and two findings withdrawn, including one that wrongly blamed the public databases for a gap in our own data. See the correction note at the end.

A vulnerability scored 9.8 out of 10 sounds like something happening to you. Mostly it is not. Of the 54,012 vulnerabilities in our analysis carrying a severity score of 9.0 or higher, 626 show any evidence of ever being exploited in a real attack. That is 1.2%. The other 98.8% have sat there, scored critical, and been used against nobody.

This is not an argument for ignoring severity scores. It is an argument for understanding what they measure, because the mismatch runs in both directions and the second direction is the dangerous one.

The scores that were too low

We looked at the 1,733 vulnerabilities confirmed as exploited in the wild and asked what they had been scored.

Severity band Confirmed-exploited flaws Share
Critical, 9.0 to 10.0 626 36.1%
High, 7.0 to 8.9 919 53.0%
Medium, 4.0 to 6.9 183 10.6%
Low, below 4.0 5 0.3%

188 of the 1,733, about one in nine, sat below 7.0. A business patching strictly by the common "7 or above" rule would have skipped every one of them, and they were being used in real attacks.

One honest note that cuts against our own figure. The scores we analysed are current ones, not the score each flaw carried on the day it was published, and severity ratings tend to get revised upwards once exploitation becomes known. So the real proportion scored below 7 at the moment a defender first had to decide is higher than one in nine. We cannot say how much higher, because that history is not recorded anywhere we could read it.

What actually predicts exploitation

The severity score is built from a vector of components: how the flaw is reached, how hard it is to pull off, what privileges you need first, whether a user has to click something. The headline number blends them all.

Taken separately, some of those components discriminate and one does not.

Vulnerabilities requiring no privileges at all were more likely to end up exploited than those needing even low privileges. Vulnerabilities requiring no user interaction were more likely than those needing someone to click. Both make intuitive sense: attacks that run without help scale, and attacks that need help do not.

Attack complexity, the component that asks how difficult the exploit is to execute, did not discriminate at all. Low-complexity and high-complexity flaws were exploited at almost identical rates. That is a genuinely useful negative result, because complexity carries real weight in the severity formula. It is telling you something the evidence does not support.

We are giving these as directions, not multipliers. Only 79 of the confirmed-exploited flaws in our data carry a full scoring vector, so the counts behind those ratios are small. When we re-ran the analysis the sizes of the two effects moved and swapped order, which is exactly why we would not want you quoting them. The directions held, and so did the result on complexity.

A fifth of the record has no score at all

The 400,837 vulnerabilities in our analysis are held as 586,739 records, because several sources can each describe the same flaw. Of those records, 131,472 carry no severity score of any kind. That is 22%.

Some of that is expected. About 18,000 are rejected entries, withdrawn after being issued, which correctly have no score. Strip those out and about a fifth of the genuine record is still unscored.

Most of the rest is ordinary backlog. Scoring lags publication, so the newest entries look worst: 44% of 2026 records were unscored when we looked. Older years are mostly complete. For 2023 the figure is 8%, for 2024 it is 4%, and for 2025 it is 10%.

The practical consequence falls on whatever is new. Any tool, policy, or standard that filters by severity is silently ignoring more than two in five of this year's entries, at exactly the point when a decision has to be made about them.

What to do with this

  • Treat a critical score as "look at this", not "this is happening". Check whether anything suggests real-world exploitation before you declare an emergency out of hours.
  • Do not let a threshold be your only filter. Anything scored below your cutoff, or carrying no score yet, never reaches you at all. That is where one in nine of the real attacks were hiding.
  • Look at the vector, not just the number. No privileges required and no user interaction needed are the two components worth reading. Attack complexity, on this evidence, is not.
  • Ask what happens to unscored vulnerabilities in whatever tool or service you use. "It has no CVSS yet so it did not appear" is a real failure mode for anything recent.

How Steelwise can help

If you want a straight answer about whether your current patching approach is missing the things that matter, that is exactly the kind of question a security review answers. Get in touch.

About the data. Figures come from our analysis of 400,837 distinct public vulnerabilities sourced via StackFlag, which is a Steelwise product, queried on 4 October 2026. The underlying data is public: the National Vulnerability Database, CISA's Known Exploited Vulnerabilities catalogue (version 2026.10.02, 1,733 entries), and GitHub Security Advisories. Exploitation is measured against CISA's catalogue, which records confirmed exploitation rather than all of it, so every figure here is a floor.

If you spot an error in this filing, tell us and we will correct it and note the change.

Further reading

Correction

4 October 2026, 16:06 BST. This filing was first published on 31 July 2026, under the title "97% of critical vulnerabilities are never exploited by anyone", using a dataset that turned out to be incomplete. A fault in StackFlag had silently failed to store about 180,000 records from the National Vulnerability Database. We re-ran the analysis on the complete data. The figures have been revised throughout, and two findings are withdrawn.

Withdrawn: the claim about 2023. We reported that 36.8% of 2023 records were still unscored and said it looked like "a specific period where the scoring effort upstream fell behind and never caught up". That was wrong. On complete data the figure is 8.3%. The gap was in our own collection, not in the public databases, and we should not have attributed it to them.

Withdrawn: the unscored exploited flaws. We reported that 141 confirmed-exploited vulnerabilities "carried no severity score at all". None do. Every one of the 1,733 entries in CISA's catalogue has a score. The 141 were empty leftover records in our own store.

Revised. The share of critical-scored vulnerabilities with any exploitation evidence is 1.2% (626 of 54,012), not 2.8% (570 of 20,491), so the headline is 99%, not 97%. The share of exploited flaws scored below 7.0 is about one in nine (188 of 1,733), not one in eight. The unscored share of the whole record is 22%, not 31%. We previously described two scoring components as each making exploitation "roughly three times more likely"; the sizes of those effects changed on re-analysis, so we now give the direction only. We now count distinct vulnerabilities, not database records, except where stated.

← All filings